#AADInternals Azure AD & Microsoft 365 kill chain shows how different attacker roles can get access to #AzureAD and #Microsoft365.
Pro tips:
1. Use MFA!
2. Avoid inviting unnecessary guests
3. Minimize # of Global Admins
4. Protect your on-prem servers
o365blog.com/aadkillchain/
He copied a value out of the Windows Event Log.
Pasted it into his special browser.
And he was signed into Microsoft Entra as the user who had just authenticated.
No password. No phishing link. No stolen private key.
@MGrafnetter's Black Hat USA 2026 research...
A record-breaking year for Microsoft's Bounty Programs!
This year, Microsoft awarded more than $20 million to 562 security researchers, the highest total payout and largest number of researchers recognized in program history.
Read the full blog to learn more about the impact of the global security research community: aka.ms/microsoft-bounty-year…
For those that missed it the Active Directory tier model documentation recently had a huge uplift, and even more importantly, the scripts used to configure your AD in line with this tiered model (tier 0-1-2) have been fully open sourced for your use.
The updated repo also contains scripts to audit drift from the baselines, and a detailed FAQ to help you deploy the model.
github.com/microsoft/ActiveD…
Visited this week the mothership 🚀in Redmond! Compulsory morning run yesterday 10k, today 6k 🏃♂️
Met a lot of old and new colleagues, also bumped into @RebeccaPattee and @nicfill from @msftsecresponse 🤟😎👍
Ever wondered how a certain cli flag in ffuf works? I just rewrote the whole ffuf documentation, and one of the ways to browse it is through cli flag reference. Check them out: github.com/ffuf/ffuf/wiki/CL…